First published: Tue Aug 19 2014(Updated: )
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | <=7.0\(3\)n1\(1\) | |
Cisco NX-OS | =5.0\(2\)n1\(1\) | |
Cisco NX-OS | =5.0\(2\)n2\(1\) | |
Cisco NX-OS | =5.0\(2\)n2\(1a\) | |
Cisco NX-OS | =5.0\(3\)n1\(1c\) | |
Cisco NX-OS | =5.0\(3\)n2\(1\) | |
Cisco NX-OS | =5.0\(3\)n2\(2\) | |
Cisco NX-OS | =5.0\(3\)n2\(2a\) | |
Cisco NX-OS | =5.0\(3\)n2\(2b\) | |
Cisco NX-OS | =5.1\(3\)n1\(1\) | |
Cisco NX-OS | =5.1\(3\)n1\(1a\) | |
Cisco NX-OS | =5.1\(3\)n2\(1\) | |
Cisco NX-OS | =5.1\(3\)n2\(1a\) | |
Cisco NX-OS | =5.1\(3\)n2\(1b\) | |
Cisco NX-OS | =5.1\(3\)n2\(1c\) | |
Cisco NX-OS | =5.2\(1\)n1\(1\) | |
Cisco NX-OS | =5.2\(1\)n1\(1a\) | |
Cisco NX-OS | =5.2\(1\)n1\(1b\) | |
Cisco NX-OS | =5.2\(1\)n1\(2\) | |
Cisco NX-OS | =5.2\(1\)n1\(2a\) | |
Cisco NX-OS | =5.2\(1\)n1\(3\) | |
Cisco NX-OS | =5.2\(1\)n1\(4\) | |
Cisco NX-OS | =5.2\(1\)n1\(5\) | |
Cisco NX-OS | =5.2\(1\)n1\(6\) | |
Cisco NX-OS | =5.2\(1\)n1\(7\) | |
Cisco NX-OS | =5.2\(1\)n1\(8\) | |
Cisco NX-OS | =5.2\(1\)n1\(8a\) | |
Cisco NX-OS | =6.0\(2\)n1\(2\) | |
Cisco NX-OS | =6.0\(2\)n1\(2a\) | |
Cisco NX-OS | =6.0\(2\)n2\(1\) | |
Cisco NX-OS | =6.0\(2\)n2\(1b\) | |
Cisco NX-OS | =6.0\(2\)n2\(2\) | |
Cisco NX-OS | =6.0\(2\)n2\(3\) | |
Cisco NX-OS | =6.0\(2\)n2\(4\) | |
Cisco NX-OS | =6.0\(2\)n2\(5\) | |
Cisco NX-OS | =7.0\(0\)n1\(1\) | |
Cisco NX-OS | =7.0\(1\)n1\(1\) | |
Cisco NX-OS | =7.0\(2\)n1\(1\) | |
Cisco Nexus 5000 firmware | ||
Cisco Nexus 5010 | ||
Cisco Nexus 5010 | ||
Cisco Nexus 5020 | ||
Cisco Nexus 5020p Switch | ||
Cisco Nexus 5548P Firmware | ||
Cisco Nexus 5548UP Firmware | ||
Cisco Nexus 5596T Firmware | ||
Cisco Nexus 5596UP Firmware | ||
Cisco Nexus 56128p Firmware | ||
Cisco Nexus 5672UP-16G | ||
Cisco Nexus 6001 Firmware | ||
Cisco Nexus 6004 Firmware | ||
Cisco Nexus 6004X Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3341 is considered a medium severity vulnerability that allows attackers to enumerate VLANs.
To fix CVE-2014-3341, upgrade Cisco NX-OS to a version that is later than 7.0(3)N1(1).
CVE-2014-3341 affects Cisco Nexus 5000 and 6000 series devices running vulnerable versions of NX-OS.
Yes, CVE-2014-3341 can be exploited remotely by attackers sending specific SNMP requests.
The impact of CVE-2014-3341 is that it allows unauthorized users to gather information about VLAN configurations, which can lead to further attacks.